You are not logged in.
Pages: 1
We are receveiving antivirus notification on detection, and all the details are in the body of the message (user who has triggered the threat, etc)
Is it possible to have a rule that checks for an entry like "DOMAIN\username", and adds automatically DOMAIN\username as a watcher ?
Regards,
Offline
Guess thats not possible
Offline
you ca use a script as middleware.
Let the script open the Ticket vie API an inside the script you can do all the magic you need
Offline
Pages: 1